Skip to content

Understanding AI Risk: CyberCube's I2T2 Framework with Jon Laux

Jon Laux explains CyberCube's I2T2 framework for AI risk: four dimensions, six event families, and what it means for (re)insurers.

No video selected

Select a video type in the sidebar.

Back to videos
  • 5 Minute Read

Speakers: Yvette Essen, Head of Communications and Market Engagement, CyberCube; Jon Laux, Head of Product and Analytics, CyberCube


00:00

Yvette Essen: CyberCube has recently published a new framework looking at AI-driven risk. I’m Yvette Essen, Head of Communications and Market Engagement for CyberCube. And joining me to summarize that new framework is Jon Laux, VP of Analytics and Products for CyberCube. Jon, please can you explain to me, first of all, why are we publishing this framework?

Jon Laux: Absolutely. There’s so much being written and talked about with respect to AI. A lot of it

00:27

that we see is cyber risk oriented. But there’s also a lot of cacophony, if you will, in terms of market reactions to: are exclusions being put out, is coverage being granted? I think for someone looking on, it’s felt like a lot of noise. And what we wanted to do with the framework was, first of all, distill our own thinking, but then give our clients a way to make sense of what we see going on.

00:57

AI is such a transformational technology, and there’s a lot of different ways that shows up in how it affects the economy, which means there’s a lot of ways it shows up in how it affects insurance. And so some of that is very much within the realm of cyber insurance as we’re used to it, but a lot of it’s also not. And so what we wanted to do with the framework was give people a coherent way to think about AI risk writ large, and the number of different ways it can show up that affect the insurance industry, so people can understand it and then take action

01:27

in the ways that they feel are appropriate.

Yvette Essen: Now, the framework we have called I2T2. What does that mean?

Jon Laux: Sure. So that’s what it boiled down to. We created six different event families, and then as we were looking at them, they fell into four basic dimensions of risk, which is what you’re referring to. So the first I is information, then there’s intelligence, and then there’s tactics, and then there’s the technology stack. So, briefly:

01:54

Information would be where AI causes issues simply by virtue of how it’s gathering information or the information it’s producing. A lot of that tends to be where the models run afoul of law. The models are scooping up data that they shouldn’t be. Media liability things tend to fall into that category, as an example. Intelligence is where it gets really interesting. So that’d be the second dimension. Because there’s things that AI is now doing that previously only humans were really doing.

02:24

And so gathering information, making decisions, doing things in the physical world: each of those has characteristics of it and can create different sources of liability. And so the distinctions between those then come down to the question of how much the AI is being trusted to do. Is it just providing an input, and then a human is, you know, using it to make a decision? But maybe it’s a misguided decision, a bad diagnosis, maybe, for example. The agentic

02:53

type things fall into the second category. So that would be the model makes a bad decision that has consequences. Maybe it’s biased, maybe it’s causing financial harm, things like that. And then obviously in the physical world, in the area of robotics, for example, vehicle crashes or things of that nature. The two Ts, then, are the ones that maybe are more familiar to a cyber audience. So, the realm of tactics. AI is transforming

03:21

lots of different aspects of what we might think of as the threat landscape, for example, as well as the financial crime side of things: business email compromise, things of that nature. And then finally, the technology stack itself. So it’s not wrong to think about AI as a new set of single points of failure the way that we would, but it’s not just the foundation models themselves. It’s the data centers that are supporting them, it’s the energy contracts that support them. So there’s a whole technology stack that’s obviously being built out around that. And so there’s

03:51

layers of systemic exposure in each of those areas. So that’s what we wanted to kind of package up in the framework. It’s a little fun in terms of how we put it together. But what we’ve begun to do is think about what different kinds of events and loss types could look like within each of those quadrants and the event families we put together in it.

Yvette Essen: So this framework is out there. What do we anticipate people will use it for? What’s the insurance industry going to utilize that framework for?

04:19

Jon Laux: Yeah, so, I mean, as we saw with silent or non-affirmative cyber coverage, there’s a similar wave that we see happening with AI right now. Again, it’s a big technology. It forces insurers and reinsurers to look at their contracts differently, perhaps. And so we see a couple of things happening at the same time right now. The insurance industry is excluding coverage in places, generally places where they find they don’t want it, or they’re uncomfortable providing it, or they can’t underwrite to it.

04:49

They’re affirming coverage where they believe it belongs, maybe with sublimits, maybe not. And then I think as a market, we’re also testing the question of whether there’s net new coverage that needs to be offered for some of these things that haven’t really existed before. What we wanted to do with the framework was equip insurers and reinsurers to navigate those questions themselves. Each company is a little bit different; their policies work differently. If you’re a buyer looking at how your coverage is coordinated, you may have gaps, you may not.

05:19

And using this framework, you can then kind of apply it to what your situation is. This is obviously a starting point. We are beginning to do a lot on our side. We’re quite excited about it. So our existing cyber models, we’re in the process of updating for the effects that AI could have and the range of ways it could play out. We’re also thinking about new products and solutions we can bring to bear for that wider array of potential scenarios that can unfold as the risk continues to evolve.

05:47

Yvette Essen: Jon, thank you very much for that summary. Our framework can be found on our website, cybercube.com. For CyberCube, I’m Yvette Essen.